Skip to content

Compliance matrix

Digital Operational Resilience Act

European Union · Updated 2026-07-19

Applies to: EU financial entities and their critical ICT third-party providers.

Requirements mapped to CIAM

ICT access control and authentication

Access to critical financial systems must use strong authentication and least privilege.

CIAM controls

  • MFA and phishing-resistant authentication for privileged access
  • Least-privilege, reviewed access

Evidence

  • Access control policy
  • Access reviews

Ask the vendor

  • Can we enforce phishing-resistant MFA and least-privilege access for critical systems?

ICT incident detection and reporting

Identity-related incidents must be detected, logged, and reported within regulatory timelines.

CIAM controls

  • Monitoring and alerting on identity anomalies
  • Exportable audit logs for incident reporting

Evidence

  • Incident logs
  • Monitoring configuration

Ask the vendor

  • What identity monitoring and audit export support incident reporting?

Third-party ICT risk (identity providers)

Your CIAM vendor is a third-party ICT provider whose resilience and exit strategy you must manage.

CIAM controls

  • Documented resilience and SLAs
  • Exit / portability plan for the identity provider

Evidence

  • Vendor resilience documentation
  • Exit plan

Ask the vendor

  • What are your availability SLAs, and how portable is our user and configuration data on exit?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Is a CIAM vendor in DORA scope?
If your CIAM platform supports critical financial functions it is a third-party ICT provider under DORA, so its resilience, SLAs, incident handling, and your exit/portability plan all become part of your compliance. Strong authentication and audit logging for critical systems are the core CIAM controls.

Source

Regulation (EU) 2022/2554 (DORA, EUR-Lex)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.